{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-24T18:49:36.206","vulnerabilities":[{"cve":{"id":"CVE-2023-40172","sourceIdentifier":"security-advisories@github.com","published":"2023-08-18T22:15:11.017","lastModified":"2026-06-17T06:16:32.453","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. A Cross-site request forgery (CSRF) attack is a type of malicious attack whereby an attacker tricks a victim into performing an action on a website that they do not intend to do. This can be done by sending the victim a malicious link or by exploiting a vulnerability in the website. Prior to version 1.0.5 Social media skeleton did not properly restrict CSRF attacks. This has been addressed in version 1.0.5 and all users are advised to upgrade. There are no known workarounds for this vulnerability."},{"lang":"es","value":"Social media skeleton es un proyecto/framework de social media sin completar implementado usando php, css, javascript y html. Un ataque de Cross-Site Request Forgery (CSRF) es un tipo de ataque malicioso mediante el cual un atacante engaña a una víctima para que realice una acción en un sitio web que no tiene intención de hacer. Esto puede hacerse enviando a la víctima un enlace malicioso o explotando una vulnerabilidad en el sitio web. Antes de la versión 1.0.5, Social Media Skeleton no restringía correctamente los ataques CSRF. Esto se ha solucionado en la versión 1.0.5 y se recomienda a todos los usuarios que la actualicen. No se conocen soluciones para esta vulnerabilidad. "}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"fobybus","product":"social-media-skeleton","versions":[{"version":"< 1.0.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-10-02T15:31:56.610741Z","id":"CVE-2023-40172","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:fobybus:social-media-skeleton:*:*:*:*:*:*:*:*","versionEndExcluding":"1.0.5","matchCriteriaId":"C6B65799-63F2-4F3B-B6F8-BF9DD02EAB93"}]}]}],"references":[{"url":"https://github.com/fobybus/social-media-skeleton/commit/344d798e82d6cc39844962c6d3cb2560f5907848","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/fobybus/social-media-skeleton/security/advisories/GHSA-873h-pqjx-3pwg","source":"security-advisories@github.com","tags":["Product"]},{"url":"https://github.com/fobybus/social-media-skeleton/commit/344d798e82d6cc39844962c6d3cb2560f5907848","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https://github.com/fobybus/social-media-skeleton/security/advisories/GHSA-873h-pqjx-3pwg","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"]}]}}]}